LOG INREGISTER

Anti-Money Laundering & Bank Secrecy Act Policy

How we detect, prevent and report money laundering and suspicious activity.

OnPointCasino.us | OnPointCasino.com · OnPoint Administration LLC · Effective Date: April 12, 2026 · Version: 1.0 · Policy Owner: Chief Compliance Officer

1. Purpose and Scope

OnPoint Administration LLC, operating the sweepstakes gaming platform OnPointCasino.us and OnPointCasino.com (the Company), is committed to full compliance with all applicable federal anti-money laundering (AML) laws and regulations, including the Bank Secrecy Act (BSA), 31 U.S.C. Section 5311 et seq., and the regulations promulgated thereunder by the Financial Crimes Enforcement Network (FinCEN).

This Anti-Money Laundering and Bank Secrecy Act Policy establishes the framework, procedures, and controls the Company employs to detect, prevent, and report money laundering, terrorist financing, and other financial crimes involving our platform.

This Policy applies to all employees, contractors, officers, directors, and third-party service providers acting on behalf of the Company.

1.1 Regulatory Framework

  • Bank Secrecy Act (BSA), 31 U.S.C. Sections 5311-5336
  • USA PATRIOT Act of 2001 (Pub. L. 107-56)
  • FinCEN Regulations, 31 C.F.R. Chapter X
  • OFAC Regulations administered by the U.S. Department of the Treasury
  • Applicable state sweepstakes laws and regulations

2. AML Compliance Program

The Company has established a written AML Compliance Program that includes the following four pillars required by the BSA:

  1. Internal policies, procedures, and controls to prevent money laundering and terrorist financing
  2. Designation of a qualified AML Compliance Officer
  3. Ongoing employee training on AML/BSA requirements
  4. Independent testing and auditing of the AML program

2.1 AML Compliance Officer

The Company designates an AML Compliance Officer responsible for:

  • Day-to-day oversight and implementation of the AML/BSA program
  • Ensuring all required reports are filed with FinCEN and applicable agencies
  • Developing and updating AML policies and procedures
  • Coordinating employee AML training
  • Serving as the primary liaison with regulatory authorities
  • Reviewing and investigating suspicious activity alerts

2.2 Internal Controls

The Company maintains robust internal controls including:

  • Risk-based customer due diligence (CDD) procedures
  • Automated transaction monitoring systems
  • OFAC/sanctions screening for all customers
  • Enhanced due diligence (EDD) for high-risk customers
  • Segregation of duties in financial operations
  • Periodic review of customer risk profiles

3. Customer Due Diligence (CDD) and Know Your Customer (KYC)

The Company employs a risk-based approach to customer due diligence. All customers are subject to identity verification before being permitted to conduct financial transactions on the platform.

3.1 Customer Identification Program (CIP)

At a minimum, the Company collects and verifies the following information for each customer:

  • Full legal name
  • Date of birth (to confirm minimum age of 18)
  • Residential address (no P.O. Box)
  • Government-issued identification number (SSN, ITIN, or passport number)
  • Email address and phone number

3.2 Identity Verification

The Company utilizes Sumsub, a third-party identity verification provider, to conduct the following checks:

  • Government-issued ID document verification (passport, driver's license, state ID)
  • Biometric facial comparison (liveness check)
  • Database cross-reference against global watchlists and PEP lists
  • Address verification

3.3 Customer Risk Rating

Each customer is assigned a risk rating (Low, Medium, or High) based on factors including:

  • Geographic location and IP address
  • Transaction volume and frequency
  • Source of funds
  • Adverse media or watchlist hits
  • Unusual transaction patterns

3.4 Enhanced Due Diligence (EDD)

High-risk customers are subject to Enhanced Due Diligence, which may include:

  • Source of funds documentation
  • Source of wealth documentation
  • Enhanced transaction monitoring
  • Periodic account reviews
  • Senior management approval for account maintenance

4. Transaction Monitoring

The Company maintains an automated transaction monitoring system designed to identify transactions or patterns that may indicate money laundering, terrorist financing, or other illicit activity.

4.1 Monitoring Parameters

  • Large cash equivalent transactions exceeding reporting thresholds
  • Structuring or smurfing patterns designed to evade reporting requirements
  • Rapid deposit/withdrawal cycles without corresponding play activity
  • Multiple accounts linked to the same individual or device
  • Transactions inconsistent with the customer's stated profile
  • Unusual geographic patterns, including VPN/proxy usage
  • Dormant account reactivation with sudden high-value activity

4.2 Alert Investigation

  1. Review transaction history and customer profile
  2. Request additional documentation from the customer if warranted
  3. Escalate to the AML Compliance Officer
  4. File a Suspicious Activity Report (SAR) if required
  5. Restrict or terminate the customer account as appropriate

5. Reporting Obligations

5.1 Suspicious Activity Reports (SARs)

The Company will file a SAR with FinCEN when the Company knows, suspects, or has reason to suspect that a transaction involves funds from illegal activity, is designed to evade BSA requirements, has no lawful purpose, or involves $5,000 or more meeting the above criteria. SARs are filed within 30 days of initial detection.

5.2 Currency Transaction Reports (CTRs)

To the extent required by applicable law, the Company will file Currency Transaction Reports (CTRs) with FinCEN for transactions exceeding $10,000 in currency.

5.3 Record Retention

All AML/BSA records are retained for a minimum of five (5) years, including customer identification records, transaction records, SAR filings, training records, and audit reports.

6. OFAC and Sanctions Compliance

The Company screens all customers against the OFAC Specially Designated Nationals (SDN) list and all applicable sanctions lists. No transactions may be conducted with sanctioned individuals, entities, or jurisdictions. Screening is performed at account opening and on an ongoing basis. Confirmed matches result in immediate account restriction and reporting to OFAC as required.

7. Prohibited Activities and Restricted Jurisdictions

The Company does not permit account registration or transactions from:

  • Any country, territory, or individual subject to OFAC comprehensive sanctions
  • Jurisdictions where online gaming or sweepstakes are prohibited by law
  • Individuals identified as money launderers, fraudsters, or bad actors
  • Individuals under the age of 18

8. Employee Training

All employees with AML/BSA responsibilities receive training at onboarding and annually thereafter, covering AML laws and regulations, recognition of suspicious activity, reporting procedures, and consequences of non-compliance. Training completion is documented and retained.

9. Independent Testing and Audit

The Company conducts or commissions an independent review of its AML/BSA program at least annually, assessing adequacy of policies, effectiveness of monitoring systems, accuracy of filings, and training adequacy. Findings are reported to senior management and remediation is tracked.

10. Non-Retaliation Policy

The Company prohibits retaliation against any employee who, in good faith, reports suspected violations of this Policy or applicable laws. Any retaliation is grounds for immediate disciplinary action up to and including termination.

11. Policy Review and Updates

This Policy is reviewed and updated at least annually or upon any material change in law, regulations, or business operations.

Document Approval

This document has been reviewed and approved by authorized representatives of OnPoint Administration LLC.

Authorized Signatory — Chief Compliance Officer. OnPoint Administration LLC | OnPointCasino.us | OnPointCasino.com. Date: April 12, 2026.

Questions about this policy? Contact support@onpointcasino.com.